T08 · Insecure Dependencies
- Location
SKILL.md:94- Finding
Execution of Untrusted Project Build Code and Dependencies
- Content
View full analysis
-f environment.yml --prune CONDA run -n pip install . CONDA run -n pip install -r requirements.txt CONDA run -n pip install . CONDA run -n pip install pipenv && CONDA run -n pipenv sync ``` ### Technical Analysis The Skill directs the Agent to install dependencies and the current project without first establishing that the project or its dependency manifests are trusted. The `pip install .` operation may execute project-controlled build logic through a Python build backend or legacy `setup.py` behavior. An attacker can place malicious execution logic in a repository's build configuration and cause it to run during package metadata generation, wheel construction, or installation. The other commands consume project-controlled dependency manifests. These manifests can select untrusted package names, package indexes, direct URLs, VCS repositories, Conda channels, or packages vulnerable to dependency confusion. The instructions do not require lock files, package hashes, source restrictions, manifest review, or explicit user approval before installation. Although installation is intended to occur in a Conda environment, package build code executes as the user running the Agent. A virtual environment isolates Python packages but does not sandbox filesystem, process, credential, or network access. ### Attack Path 1. An attacker creates or modifies a Python project containing one or more of the following: - A malicious build backend or `setup.py` implementation. - A dependency with an attacker-controlled name or source. - A direct URL or VCS dependency hosting malicious package code. - A malicious Conda channel or package selection. 2. The victim asks the Agent to configure a ...[truncated 977 chars]- Remediation
View remediation
